Hacker Newsnew | past | comments | ask | show | jobs | submit | NavinF's commentslogin

Does anyone use it though? Apparently ANEForge got 16.8 tok/s of Qwen3-8B + 0.6B draft using private APIs. Not big enough

turns out the overlap between "people who can't configure their webserver to serve at wire speed" and "people who can get law enforcement to take them seriously" is the empty set


Didn’t read the article, huh?


Oh I did. They're complaining about literally 14 cores across all of git.kernel.org. Definitely not in the "people who can get law enforcement to take them seriously" group.


>I had Claude write a tool to patch out the table entry for camera activity, fix up the integrity hash, and flash it to the camera. A quick test showed that the green LED that normally illuminates while recording no longer turned on. Horrifying!

Oof. Apple claims this is not possible for macbook cameras because the LED can't be controlled from software. Wish more manufacturers would do the same.


> the LED can't be controlled from software

If you look at tear downs apparently it is connected to the webcam so it is energized when the webcam receives power making it nearly impossible to defeat.

You can say a lot about Apple but the engineering is clever at the hardware level.


Also the Hall effect sensor disabling the mic when a MacBook lid is closed, apparently just about impossible to bypass. https://en.wikipedia.org/wiki/Hall_effect


It's not. I can place my iPhone next to my trackpad and the MacBook thinks I closed the lid.


That's not what people mean by 'bypassing', turning it off is obviously easy. The point is that activating the microphone while the lid is closed is pretty much impossible.


It's not even that clever, really. The camera power rail must be physically close to the camera, so it's trivial to hang an LED off it. A device manufacturer has to go out of their way to make it so the LED and camera function are independent, and I'm sure many do, for the worst reasons you can possibly think of.


It's more a testament to how little most companies care. The solution is simple and yet most products are defective.


For most products the LED is not a simple on/off indicator. It signals device state, user confirmations, ota updates, etc etc etc.

I’m at a loss for how you would signal all of that without a GPIO.


The record indicator should be purely reserved for showing if the camera is on. If you want to show all that other stuff, put a second LED on it.


Nest cameras used to have a user toggle to enable/disable the camera LED; not the worst reason I can think of.


Yeah, and then came people hiding cameras in places where you clearly did not want a camera to be. Bathrooms in public areas, hotels, workplaces and AirBnBs are a much too common issue, it's like daily news some creep gets busted for running cameras.


Yeah, my implication was just that the worst thing I could think of were cameras where the owners don't realize that some third-party is recording them.

LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.


> Yeah, my implication was just that the worst thing I could think of were cameras where the owners don't realize that some third-party is recording them.

At the point we are in time... honestly, I don't expect this thing called "privacy" any more. And I'm, notably, German. Glassholes, camera surveillance everywhere, our police is more and more turning into the rabid hellscape that is American police with far-right authoritarians at the helm and more and more forces joining up with Palantir or working on a European alternative.

I'm dead sure that at least law enforcement plus dedicated individuals with access to ad data brokers can work out precisely when I had a wank and what I wanked to, now there being a video of me wanking would only be the icing on the cake.

> LEDs won't stop creeps — the camera owner can always disable LEDs with a bit of electrical tape.

Many even forget about that piece of opsec, which is why they get caught in the first place, eventually the tape falls off.


It could be a typical design that the camera and LED always have power, and the LED is switchable.

Giving the camera plus LED a separate power supply means that the camera has to boot or come online, which maybe increases the dwell time. And the camera is not visible on the USB bus when powered off.

I think there's more engineering to Apple's design than it first seems.


The thing visible on the bus is the interface chip, not the sensor. Most cameras which I've seen hardwire their activity LEDs (it is impossible to grab stills or record video without lighting up the LED) do so by connecting the activity LED to the sensor power rail. With the sensor powered off, the device is still visible on the bus but you get no usable image data.


This still would allow one to "strobe" the power line making it impossible for a human to see the LED but the camera could still capture snapshots and at a decent framerate even.


Naw the LED stays on a little longer after you stop capturing image data. They either have burned in firmware or a simple circuit (RC and comparator) that stops your attack.


One of my old Logitech webcams have its recording light wired up to V4L2 protocol directly. I can change its recording light mode (on/off/blink) from software by changing recording light mode directly. Wonder whether that Insta360 also had that.

I'd have tried that first before diving into the firmware head-first.


Apple also claims that iMessage is end to end encrypted. Their privacy stance is 99% posturing.


The teardown showed this is the 1% right?

Also I thought you could trust iMessage if, unlike everyone, you disabled iCloud backup (and, unlike everyone, so did the recipient). Perhaps a way for the feds to be able to pin dumb criminals while giving investigative journalists & dissidents a way to stay safer.


According to Apple, you can have iCloud backup enabled while maintaining E2E encryption with their Advanced Data Protection option:

https://support.apple.com/en-us/102651#advanced

You do have to be sure to not enable web access via icloud.com


You also have to make sure everyone you contact did this, which is impossible.

Much easier to use a 3rd party app like Signal.


Even with "E2E" encryption with iMessage, you're still trusting Apple completely and totally with key distribution. If a new device is added to your account by an attacker or by Apple themselves, your existing devices will happily loop them in to share iMessage access with them. The vast, vast majority of iMessage users are never going to dig into the Apple keychain app to actually check what keys are being trusted and this is something that can be targeted to a single account so no one outside of Apple never even needs to know it happened.


CKV aims to cover that case:

https://support.apple.com/en-us/118246

https://support.apple.com/en-us/118247

> An unrecognized new device was added to that person’s Apple Account. This alert might mean that the person you are messaging has an issue with one of their devices, or that a sophisticated attacker might be attempting to eavesdrop on the conversation.

My understanding is that iMessage implements PFS. To get around PFS and access older messages, one needs to get their hand on a backup, which needs fully enrolling a device, not just messaging key exchange hackery.

And as far as trusting Apple with key exchange, well, if you're running their OS and hardware, I suppose that trust of key exchange is the least of your concern (or part of the whole deal anyway depending on how you look at it)


Uh-oh, I have that turned off. I’m used to seeing a message when someone on Signal gets a new phone, but I’d be none the wiser with a snooper on iMessage. Any downsides to enabling you know of? Assuming all my logged-in devices are on a current/supported version.


WebUSB has been live in Chrome for 9 years and nothing happened. Compare to all the features that result in people getting hacked every day. Your threat model is ridiculous.


Look, I find it funny that I find myself arguing on the other side of the discussion that I'm frequently on, but here is where I draw the line, and I think what is ridiculous is to think otherwise.

How many hoops Google asks you to go to install an Android app ? (Androids amounts to basically the most sandboxed environment one can have today; malware installed there can practically do _nothing_) MANY. Centralized register of apps and remote blacklisting, a lot of permission prompts, password check, and they are even literally pushing to even have a physical 24h cool-off period if you skip the centralized register.

How many hoops does Google ask you to go an allow a random website unfettered access to destroy your hardware? One. Permission. Prompt. In a bubble prompt, that barely registers above noise compared to other permission prompts browsers ask.

Of course these are two ridiculous extremes, but they exemplify the point. There is a reason a browser won't allow a random website to write over random sectors of your hard disk just because you said "accept" to a bubble-style permission prompt about wanting to "save files to your hard disk". The line has to be drawn somewhere, and allowing what basically amounts to raw access to IO ports just after a single permission prompt listing the device name is where I draw it. Any user, even knowledgeable ones, is simply going to be _incapable_ of truly understanding the risks behind allowing this access.

I would be much more in favor of allowing random IPC to services in your local computer (after a permission prompt) than this., something that is equally useful if not more than allow raw access to HID.

Devices need to be hidden behind drivers that multiplex and control access to the device at the OS level. A bus that was never meant to be exposed to user-level access should not be exposed to random programs much less websites. This is not security, this is "mistake prevention" level, in the same way operating systems disallow a random user-level program from overwriting the hard disk.

And do not read this as "devices should sign their firmwares and what not". That is (for me) definitely the wrong take but literally the only take that is left on the table due to Google's stupid behavior.


> How many hoops Google asks you to go to install an Android app ? (Androids amounts to basically the most sandboxed environment one can have today; malware installed there can practically do _nothing_) MANY. Centralized register of apps and remote blacklisting, a lot of permission prompts, password check, and they are even literally pushing to even have a physical 24h cool-off period if you skip the centralized register.

I 'member (and miss) the old Android days before everything became the locked down hellscape Android is these days. And I also member why it became that way, there was a loooot of bad actors exploiting that open model.

For operating systems it's similar. DOS/Windows up to and through ME didn't have the concept of different user levels, the file system didn't allow for it, and if you had physical access to the machine it was trivial to corrupt and subvert it. Only with Windows XP, Microsoft switched the consumer OS to NT and its multi-user model.

And so it will be for WebUSB et al. First it will be a pretty open and unrestricted world, and only if there turns out to be a significant problem, security will (need to) be tightened.


A 20oz/medium coke/pepsi is $2 (McDonald's) to $3 (Wendy's, KFC, Burger King, etc). The majority of people buy one with an entree at all those places. Revealed preference vs you living in a bubble.


lawsuits for what? AFAIK you have no right to privacy in this sense


Legislating that all complex computing devices must give out your birthday (technically a "signal" of which bucket you're in, but sites are absolutely going to keep track of which bucket you where in, keep asking, and see when it changes).

It's constitutional case law that there's an implicit right to privacy in the constitution. I don't see a law that you must wear a band with your birthday out in public passing muster based on that. I don't see why existing in cyberspace changes the inherent privacy question, and in fact makes it more meaningful given ease of automation.


> It's constitutional case law that there's an implicit right to privacy in the constitution.

Constitutional scholar here! I mean, yes, that's true in a very general sense, but no court has held that age verification to gain access to a service, or even a device, is unlawful in practice.


Novice, but I'd argue that Dobbs has seriously eroded that case law. The right to privacy used to be pretty settled law, but now the foundation of that settled law is on sandy ground.


It was never really all that settled, IMO. Roe v. Wade (which is now dead) was built on a pretty shaky foundation that was inspired by emanations of privacy rights like the Fifth Amendment, in the absence of clear Constitutional language that made a privacy right explicit.


Not yet they haven’t. Not yet.



What percentage of buyers do you imagine are gonna buy a battery big enough to saturate 15A*120V=1800W for long? The average home uses 30 kWh per day = 1250W. Batteries don't need to handle peak load. Approximately nobody has a whole home UPS.

Also 240V power strips are fairly common in my circles because GPU server PSUs tend to be more efficient at 240V. They're marketed as PDUs, not strips. You're not gonna install a new outlet for every server. One dryer outlet in the garage is enough for most people


I'm not clear what point you're making about PDUs.

Re 120V outlets, while batteries don't need to supply the full peak load, they are more effective the more of it they can supply. And a home with a heat pump or baseboard heaters, electric range, EV charger, or dryer for example is going to at times significantly exceed the capacity of the 120/15 outlet. Doesn't mean the battery would be useless, just that it wouldn't be as effective at its primary purpose of load shifting as a 240V system, and therefore less economical.


My point about PDUs is that "people don't tend to have one just free" is irrelevant. It's easy to split a 240V outlet into multiple outlets. One of them can be used to inject power. The copper doesn't care which way the electrons go.

Heat pumps and baseboard heaters are pretty uncommon in the US. Natgas furnaces are nearly 100% efficient so I don't expect that to change any time soon


Oh, I see. Yeah, good point about splitting a 240V outlet. Not as convenient as having them everywhere, but it'd certainly be possible.

NG may be 100% efficient, but heat pumps are like 300%+ in terms of electricity to indoor heat. And you get air conditioning.


> What percentage of buyers do you imagine are gonna buy a battery big enough to saturate 15A*120V=1800W for long?

You can get 10kWh of batteries and a 5kW MPPT chargeverter for a little over $2k these days (UL certified). A 30 kWh system with inverter can be had for around $4k. That’s well within the reach of most households.


FreeCAD on desktop is much the same in my experience. If LLMs were mainstream a few years ago I would have assumed the UI was 100% AI generated with zero human input besides a oneshot prompt.


When was the last time that you used FreeCAD? Even 18 months ago, I would agree with you that it was a buggy mess, but I tried it a few weeks ago and it was super stable. The UI is still a little confusing, but that just comes with the domain, since AutoCAD and Fusion 360 aren't much better.


I couldn’t get the results described by the intro tutorial 3 months ago, in the parts bench drawing a polygon, snapping was broken.


If Solidworks and Onshape were born after the birth of LLMs, they'd probably be glitchy as hell.


Insulin is $25 at Walmart for a vial that lasts a month. 2 vials if you’re fat. Find out where you read about “astronomically high insulin prices” and consider what else that author lied about


Yup, what drove that price drop, was it a technical breakthrough?

Given that in 2019 10ml of insulin outside of USA was what $20? in the USA it was ~250?


Not aware of any price drop. Walmart always sold dirt cheap insulin and it was never $250. You’re thinking of brand name insulin.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: